This runbook assumes the agent is managed by systemd and events are emitted as JSON either to stdout or journald.
systemctl status aegisbpfjournalctl -u aegisbpf -n 200 --no-pagersudo aegisbpf healthsudo aegisbpf stats or sudo aegisbpf metricsaegisbpf_net_blocks_total and aegisbpf_net_ringbuf_drops_total in metrics outputEvents include pid, ppid, cgid, comm, path, and action.
policy show to view the active policy.block list to inspect deny entries.policy export to map allowlisted cgroups to paths.sudo aegisbpf allow add /sys/fs/cgroup/<service>sudo aegisbpf block del /pathsudo aegisbpf policy apply <file> --reset/etc/default/aegisbpf and set AEGIS_MODE=--auditsudo systemctl restart aegisbpfsudo systemctl stop aegisbpfjournalctl -u aegisbpf --since "<time>" > /var/lib/aegisbpf/aegisbpf.logsudo aegisbpf policy show > /var/lib/aegisbpf/policy.applied.backupsudo aegisbpf metrics --out /var/lib/aegisbpf/metrics.promsudo aegisbpf stats > /var/lib/aegisbpf/stats.txtsudo aegisbpf policy export /var/lib/aegisbpf/policy.exportAutomated collection:
sudo AEGIS_BIN=/usr/bin/aegisbpf scripts/collect_incident_bundle.sh /var/lib/aegisbpf/incident-<ticket>This creates a compressed evidence bundle with health, metrics, policy, service status, and recent journald logs.